Start with three questions

Before anyone declares a loss permanent, answer these:

  1. Could another copy exist? Check backups, snapshots, version history, sent email, exported files, old devices and synchronised computers.
  2. Does the required key still exist? Encrypted data may be physically intact while remaining unreadable without an authorised unlock route.
  3. Where did the loss happen? A laboratory can examine a device presented to it. It cannot browse a provider’s cloud servers or reverse a completed account-side deletion.

These questions are deliberately plain. They prevent two expensive misunderstandings: sending perfectly healthy hardware to a lab for a cloud-account problem, and erasing a device because an encryption screen was mistaken for corruption.

The four hard boundaries

Boundary What has happened Realistic next route
Provider-controlled data The wanted copy exists, or existed, only inside iCloud, Google, Microsoft, WhatsApp or another service. Use the provider’s deleted-item, backup and account-recovery tools.
Missing cryptographic access The data remains encrypted and the password, recovery key or authorised device is unavailable. Search every legitimate key and escrow location before resetting anything.
The information no longer exists The relevant bytes or keys were overwritten, discarded or securely erased. Look for another version or copy; the erased representation cannot be reconstructed.
Physical information loss The part of the platter or flash memory holding the data is missing or destroyed. Assess intact areas for a possible partial recovery.

Ownership and legal authority are another gate. They can establish who is allowed to request access, but they do not defeat encryption and do not create a missing copy.

Overwritten is different from deleted

Deleting a file usually changes the file system’s record of what is available. On some storage, the old content may remain for a time until something else uses the same space. Overwriting is the later event: new information replaces the previous information at the relevant storage location.

Once the bytes have been replaced, software cannot reason backwards from the new file to the old one. The remaining routes are copies outside that location:

  • cloud or local version history;
  • snapshots;
  • email attachments;
  • temporary exports;
  • another person’s copy;
  • a backup that predates the overwrite.

This is why continuing to use a device after deletion is risky. Installing recovery software, downloading it to the affected drive and saving recovered files back to the same place all create new writes.

SSD deletion and TRIM

An SSD adds another layer. Windows and other operating systems can send TRIM or unmap information to tell the storage device which logical ranges are no longer needed. The controller may then stop returning the previous content and later erase the underlying flash as part of its own housekeeping.

Microsoft describes TRIM as a hint sent to storage media, not as a universal promise about exactly when every controller removes every old cell. That distinction matters.

The honest answer is therefore “often unrecoverable after TRIM has taken effect”, not “every deleted SSD file disappears instantly”. Device type, controller behaviour, command completion and subsequent use all affect what can still be read. Stop using the SSD if the loss matters; do not manufacture certainty by continuing to write to it.

Secure erasure is designed to defeat recovery

A completed, correctly chosen sanitisation process has a different purpose from ordinary deletion. NIST’s current SP 800-88 Revision 2 defines media sanitisation around making access to target data infeasible for a given level of effort.

That does not mean every button labelled “erase” achieved the same result. Clearing a file-system table, overwriting addressable storage, invoking a device sanitise command, cryptographically erasing a key and physically destroying media are different operations.

It does mean that a verified sanitisation process should not leave a commercial recovery route. If an organisation needs evidence that disposal was completed correctly, the question is about records and verification, not trying to recover a sample afterwards.

Encryption can preserve the data and still make it inaccessible

BitLocker, FileVault and modern phone encryption are not surface damage. They transform the stored information so it cannot be interpreted without the required secret or authorised environment.

A lab may be able to repair electronics, stabilise a failing drive or image readable storage. The result remains encrypted. The hardware work and the cryptographic access problem do not cancel each other out.

Microsoft states that it cannot retrieve, provide or recreate a lost BitLocker recovery key. Apple’s current passcode guidance says that regaining access to an iPhone after the passcode is forgotten requires resetting the device, which erases the data currently on it.

Those are not vendor sales policies that another workshop can ignore. They are consequences of the security design. Claims to “bypass” them deserve scepticism.

A factory reset is not a hardware fault

On a modern phone, treat a completed factory reset or Erase All Content and Settings as the loss of the local copy. Apple says a factory restore erases the device’s information and settings before installing the operating system again.

The useful work happens elsewhere:

  • check iCloud, Google Photos or another synchronised library;
  • check computer backups;
  • check app-specific backups;
  • check an older phone or tablet;
  • confirm that the reset actually completed rather than merely resetting settings.

Do not send a reset handset to a laboratory with the expectation that a memory chip can simply be removed and read. Modern device encryption is designed so the raw storage is not a folder of recognisable photographs.

Cloud deletion belongs to the provider route

Datraction cannot access Apple, Google, Microsoft, Meta or another provider’s servers. If a photo or document was deleted from a cloud account, use the provider’s Recently Deleted, bin, recycle and account-recovery routes first.

If the provider has permanently removed the item and no synchronised, exported or backed-up copy exists, there is no physical device containing that provider-side copy for a laboratory to inspect.

A failed phone or laptop may still matter if it holds a separate local copy that never synchronised the deletion. That is a device question, not cloud recovery.

Physical destruction may leave a partial answer

Physical damage is rarely uniform. A scratched platter may contain readable regions away from the damage. A broken memory device may have intact components. A fire-damaged drive may have lost some surfaces and preserved others.

No one can recreate information from recording material that is absent. The useful question is whether the remaining intact areas include complete files, fragments or none of the required data.

This is where “possible” and “complete” must be kept separate. An assessment may support partial recovery without supporting a promise that a named folder survives.

When not to request a quote

Do not pay for a device diagnosis when:

  • the wanted data existed only in a cloud account;
  • a modern phone was successfully erased and no backup exists;
  • the only encrypted copy remains intact but every authorised key is gone;
  • the relevant file bytes are known to have been overwritten;
  • a verified sanitisation process completed successfully.

Use the official provider or account route instead. Datraction will not ask you to send hardware merely to repeat that no hardware recovery path exists.

Request a device assessment when the last copy may still be on failing media, when the extent of overwrite is unknown, or when physical damage may have left readable areas. The value of an honest diagnosis is sometimes a recovery plan and sometimes a clear reason to stop.

Questions people ask next

Can overwritten files be recovered?
Not from the bytes that have been replaced. A laboratory may find another copy, an older version, a snapshot or unaffected fragments elsewhere, but it cannot infer the original contents of storage locations now occupied by different data.
Can a laboratory recover data without a BitLocker or FileVault key?
Physical recovery and decryption are separate. A laboratory may stabilise failed storage and obtain an image, but correctly encrypted data still requires an authorised unlock route. Repairing the hardware does not recreate a missing recovery key.
Can Datraction recover files directly from iCloud or another cloud provider?
No. Datraction has no access to provider servers or account recovery systems. Use the provider’s Recently Deleted, recycle-bin, backup and account-support routes first. A physical device matters only if it may still hold a separate local copy.
Does severe physical damage always mean nothing can be recovered?
No. Damage can be localised, leaving readable areas elsewhere on a platter or memory package. The realistic outcome may be partial rather than complete recovery. Information recorded on material that is missing or destroyed cannot be recreated.